<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: sswam</title><link>https://news.ycombinator.com/user?id=sswam</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 06:20:19 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=sswam" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>they do protect the Government...</p>
]]></description><pubDate>Tue, 10 May 2011 00:00:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530694</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530694</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530694</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>Let's say that, like most everyone else in the world, they already know how to break firefox and internet explorer, etc.  They don't want to spy on your net, they want to steal your files.</p>
]]></description><pubDate>Mon, 09 May 2011 23:58:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530688</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530688</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530688</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>s/ those who are willing to pay / those (ONLY) who asked for and funded research into such a hack /</p>
]]></description><pubDate>Mon, 09 May 2011 23:56:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530682</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530682</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530682</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>The Govt in question is obviously the US Govt.  They want to know how to break Chrome, and every other net-facing app, so that they can hack your computer and spy on you, whoever you might be.  Did you know, the CIA does do espionage?</p>
]]></description><pubDate>Mon, 09 May 2011 23:55:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530678</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530678</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530678</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>maybe Govt is envious because Google is already more powerful and capable and certainly better liked than it!</p>
]]></description><pubDate>Mon, 09 May 2011 23:53:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530672</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530672</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530672</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>I thought Pwn2own didn't even try to?</p>
]]></description><pubDate>Mon, 09 May 2011 23:52:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530671</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530671</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530671</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>they did say "exclusive"</p>
]]></description><pubDate>Mon, 09 May 2011 23:51:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530669</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530669</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530669</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>so google can fix it for 99% cases with ulimit or similar windows thing.  problem solved</p>
]]></description><pubDate>Mon, 09 May 2011 23:49:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530662</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530662</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530662</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>I can fix it right now.  Delete the flash player - problem solved.  Chrome still works.</p>
]]></description><pubDate>Mon, 09 May 2011 23:47:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530658</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530658</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530658</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>one is not obliged to prove innocence in a sensible court of law</p>
]]></description><pubDate>Mon, 09 May 2011 23:46:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530656</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530656</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530656</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>I forgot to mention - Chrome, it's written in a dialect of C, right?  Ahahahhahaha!!  and there goes any chance of security right there.</p>
]]></description><pubDate>Mon, 09 May 2011 23:34:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530631</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530631</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530631</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>VUPEN cracks Chrome for the Government!!!!!  On Windoze, even!<p>I would have thought if they really had a US govt / CIA / military / espionage customer, said customer would NOT want them to reveal ANYTHING about the exploit to Google nor the public, especially not its existance.  So, they told us that there is an exploit, and now it's top hax0r news, might likely feature in mainstream news.  Most sensible people will most likely hear of it, and will disable flash / plugins in chrome until someone fixes it.  Any worthy target for netspionage with any money and brain will hear about it immediately, and quit using chrome for lynx, dillo, or something even simpler.<p>Anyone who uses such a large app as a modern over-engineered web HTML5 bugzilla-feeding browser is kissing security goodbye forever.  GNU ls(1) may have security bugs FFS, do you think your browser doens't?  Do they include Chrome or Firefox in the 'pretty secure' OpenBSD base install?  No, no, they do not nor never will do this, although it is a most popular app!!  (also because nearly all *BSD boxes become servers, but you get my drift.)  Even if Chrome were regarded as an essential system service for every box to run, they would NOT include it!  better the system grind to a halt by itself without yielding access.<p>Google will redouble Chrome's general security and sandbox security in a push-patch, and this will most likely break the hack.  Or they will rediscover it.  LOL at your short-lived hack, your Government _will_ be pleased that you disrespected their payment and trust, boasting about it everywhere, putting Google and their targets on red-alert.<p>The 'secret black ops' part of Government would not only be displeased, they would kick their ass so damn hard for revealing that there is an exploit, that they would not be able to discover more exploits for years due to severe ass damage pain.<p>They pay you to learn stuff so we can do espionage or whatever fuckdoggery they might be intending at poor Arab countries to steal their oil, or suchlike...  Then this silly idiot hacker company posts 'woohoo we found an exploit, look at us: but we can't tell you how it works - 'tis just for our pals in the govt'.  Then the presumably nasty branch of govt gets out the concrete mixer and applies the concrete slippers - national borders not being much of an obstacle - then tosses the talkative hackers into the middle of the pacific trench (there's deep water there).  They are then eaten by those nasty deep-sea fish with big teeth, and lights on stalks to freak us out.<p>So anyway, this 'half-secret hack' business reeks deeply of bullshit to me.<p>For some real bullshit, forget everything else I said.  Windows is the utter pinnacle of bullshit for security, full stop.  I understand that certain few idiots among the population do use it for playing games, and watching porn, and trying to be hackers, and in offices, but seriously: if you use Windows, any edition of Windows, for your own security, you obviously have not a clue nor give a real fuck about your security at all.  Your password is probably 'dog' or 'cat'.  OS X and Linux are barely any better for security.<p>If you want real security, throw away all the public and commodity crap operating systems and build your own.  Or pay someone smart to build it.  If it takes you less than 5 years to debug it before deployment, or it's more than 100KB of code in total size, I guess you failed:  it's not secure.  I'll give you a hint.  Every process in the system should have access to precisely nothing by default.  Not even the CPU, not even the time of day.  Every single resource that is needed must be introduced to the process's environment by a neighbor or parent process (if possible, and in most cases it should not be).  The entire system, especially process / resource structure, privilege and connection must be visible as a nested, nodes-and-arcs graph, for the user / sysop to verify and check what the hell is going on in it.  If there's no link from Chrome to your printer, and you've disabled changes to that part of the process structure, Chrome will not ever print anything unless there's a solar storm - or similar stimulus - that miraculously alters everything without crashing it.  You ANTICIPATED THAT UNLIKELY EVENT, and made 3 or 4 systems running everying exactly the same, in parallel, in sync at each step.  If one screws up due to solar fuckdoggery, throw it in the bin and swap in another (like RAID).  They do this shit in planes I believe, not the swap in bit, until it lands.  The solar demons won't miraculously pseudo-break them all at once in the SAME WAY.<p>Windows, Microsoft, Security - can you spot the odd one out?
Can you see a juxtaposition here folks?  Can you feel it?  A disturbance ripples through the force, out through the local cluster (of galaxies) and back, because those three words were collected together in one place.<p>No amount of ill-acquired M$ money spent on Windoze security enhancements can break their appallingly bad track record for security holes, loss of privacy, and the happy virus cultivation ecosystems that Microsoft has consistently provided over the years with every version of Windows, almost from before viruses were invented.  I think the first well-made and famous exploit came well before windows was conceived, I'd suggest Ken's cc hack.  That's the first brilliant exploit I happen to know about - from the vendor himself, sly bastard.  It's hard to believe he didn't go to jail for that, anyway, heh.<p>So yeah - VUPEN, Chrome, Windoze, haX0Rz working for the Big-G Government.  LOL.  Security Jokes all around.  Chrome being the more respectable and secure among them in my opinion.  And anyone who runs a nuclear reactor that depends for its stability or continued safe operation on a computer is a cow-tipping idiot too.  Cars don't even. @stuxnet @.mil</p>
]]></description><pubDate>Mon, 09 May 2011 23:32:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530627</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530627</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530627</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>so, avoid .gov and similar :)  it's a silly TLD anyway.<p>Did the .gov pwn TPB and put their exploit up there?</p>
]]></description><pubDate>Mon, 09 May 2011 22:25:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530462</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530462</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530462</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>I don't believe this crappy little security firm has more resources than Google, even in the Security Research Dept.  They can go find it themselves and fix it.  Anyway, it's probably mostly a windows bug.  If you line the right bytes up together in windows' RAM, it will void itself and yield 'root' or whatever wiener name they have for it.  Who knows, maybe they Govt is trying to screw google, and told them to do a fake release.  Their post doesn't make them sound like real pros.</p>
]]></description><pubDate>Mon, 09 May 2011 22:24:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530455</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530455</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530455</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>"VUPEN provides vulnerability research and intelligence for defensive and offensive security."  so, they are I presume happy to help the US CIA/MIL fvck people over (who most likely don't deserve it).</p>
]]></description><pubDate>Mon, 09 May 2011 22:20:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530441</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530441</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530441</guid></item><item><title><![CDATA[New comment by sswam in "Google Chrome Hacked?"]]></title><description><![CDATA[
<p>LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser??  Don't make me laugh like that!  Poor Google, not enough money, that'll be the day.<p>These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them.<p>I prefer what VUPEN does when compared to irresponsible discoveries by black hats who do not give a shit about the integrity of the installed product and privacy / safety / security of how many millions of users, who can then be screwed over by every skript kiddie and his dog because they released the info straight to the public.<p>Sure, if the vendor has absolutely ignored you and your loud demos of the bug, and won't respond to threats to release, you might release the exploit to a small segment of the IRREPROACHABLE VANILLA WHITE HAT security community with the intention that they might help persuade the vendor to take it seriously.  That's about as far as I'd want go with releasing serious exploits.  Although of course grey/black hat stuff is fun - look, mum, I have a cool exploit!<p>If VUPEN are sworn to secrecy by their Government customer, and cannot tell the vendor or help them fix the bug, maybe it's time to get a new Government and public service.  Your Government (US arrogances with a captial G) is trying to pwn you and spy on you.  Fuck that, the government should answer to the will of the people (and don't talk to me about the farce we call democratic election.  Democracy is where (almost) all the people are deeply involved in determining policy, it's more like the ideal soviet system, really, which was not realized AFAIK.)<p>Anyway, isn't that why you're carting guns around all these years, in case your (US) Government turns nasty and starts pwning your ass up down right and left with a canoe?  (Not that it wasn't already.)  Yes indeed, guns!!  However let it not be said that I am inciting violent revolution with this sarcastic post, as I don't believe in or wish to promote that or any violent act.<p>Poor Google, not enough money.  LOL!</p>
]]></description><pubDate>Mon, 09 May 2011 22:16:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=2530420</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2530420</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2530420</guid></item><item><title><![CDATA[Obama: “Justice has Been Done”  What?  So, how many US civillians died that day?]]></title><description><![CDATA[
<p>Article URL: <a href="http://sam.ai.ki/justice">http://sam.ai.ki/justice</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=2529879">https://news.ycombinator.com/item?id=2529879</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 09 May 2011 19:28:01 +0000</pubDate><link>http://sam.ai.ki/justice</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2529879</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2529879</guid></item><item><title><![CDATA["Even a mouse can understand it, with a little coaching"]]></title><description><![CDATA[
<p>Article URL: <a href="http://sswam.wordpress.com/#yep_its_blog_spam__enjoy">http://sswam.wordpress.com/#yep_its_blog_spam__enjoy</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=2529750">https://news.ycombinator.com/item?id=2529750</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 09 May 2011 18:51:37 +0000</pubDate><link>http://sswam.wordpress.com/#yep_its_blog_spam__enjoy</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2529750</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2529750</guid></item><item><title><![CDATA[New comment by sswam in "Don't put your iPhone next to your head"]]></title><description><![CDATA[
<p>hm I was wrong, they seem to be talking about when you're making a call.  Seems to be a disclaimer in case of health problems more than a clear warning of health risks.</p>
]]></description><pubDate>Mon, 11 Apr 2011 06:43:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=2431675</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2431675</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2431675</guid></item><item><title><![CDATA[New comment by sswam in "Don't put your iPhone next to your head"]]></title><description><![CDATA[
<p>"keep the phone 5/8" away from your body"  they are talking about don't keep it in your pocket.  Brief exposure next to your head while talking should not be a big problem.  Actually I am very much concerned about mobile phone radiation, but I do think it's not actually going to cause cancer with modern handsets.  The old analog phones were a different story.  Don't talk on it too long!</p>
]]></description><pubDate>Mon, 11 Apr 2011 06:42:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=2431673</link><dc:creator>sswam</dc:creator><comments>https://news.ycombinator.com/item?id=2431673</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=2431673</guid></item></channel></rss>